Vulnerabilities > CVE-2021-29506 - Unspecified vulnerability in Graphhopper
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
NONE Integrity impact
NONE Availability impact
HIGH Summary
GraphHopper is an open-source Java routing engine. In GrassHopper from version 2.0 and before version 2.4, there is a regular expression injection vulnerability that may lead to Denial of Service. This has been patched in 2.4 and 3.0 See this pull request for the fix: https://github.com/graphhopper/graphhopper/pull/2304
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 7 |
References
- https://github.com/graphhopper/graphhopper/commit/eb189be1fa7443ebf4ae881e737a18f818c95f41
- https://github.com/graphhopper/graphhopper/commit/eb189be1fa7443ebf4ae881e737a18f818c95f41
- https://github.com/graphhopper/graphhopper/pull/2304
- https://github.com/graphhopper/graphhopper/pull/2304
- https://github.com/graphhopper/graphhopper/security/advisories/GHSA-hf44-3mx6-vhhw
- https://github.com/graphhopper/graphhopper/security/advisories/GHSA-hf44-3mx6-vhhw